Three years since its inception, the Open Smart Grid protocol is present in more than four million smart meters and similar devices around the world.
The Open Smart Grid Protocol manages communication in smart grids. It was developed by the Energy Service Network Association (ESNA), and since 2012 has been the standard of the European Telecommunications Standards Institute (ETSI), according to the study.
Two researchers, Phillip Jovanovic from the University of Passau in Germany and Samuel Neves from the University of Coimbra in Portugal, published a study exposing several encryption in the protocol.
The study, titled, “Dumb Crypto in Smart Grids: Practical Cryptanalysis of the Open Smart Grid Protocol,” explains how the encryption system used in OSGP is open to numerous attacks. The study states that “breaking” this encryption requires minimal computational effort.
Specifically, the vulnerable feature is the local verification used for the authenticity of the code identity and is called OMA Digest.
"This function is extremely weak, and cannot be considered to provide any guarantee of authenticity," the researchers say.
[signoff icon=”icon-bookmark”]“The No. 1 rule of cryptography is: Don’t invent your own”[/signoff]
It should be mentioned that experts like Adam Crain, (security researcher and founder of Automatak) who has published a study on the DNP3 protocol used in industrial communication control systems, have stated that the use of an OMA Digest function is a "big red flag", obviously meaning the riskiness of the feature.
"Protocol designers should stick to known good algorithms or even the approved NIST 'short list,'" Crain said.
"In this case, researchers who analyzed the OMA Digest found weaknesses. The weaknesses can be used to determine the private key with a very small number of tests."
Crain also mentioned "The No. 1 rule of cryptography is [Don't invent your own].".

